← Blog · · df00tech

DIVD Says Chained Zammad Zero-Days Enabled AI-Driven Breach of Its Network

security-news breach

What happened

The Dutch Institute for Vulnerability Disclosure (DIVD) has disclosed that its own network was breached via a chain of two zero-day vulnerabilities in Zammad, the open-source customer service/ticketing platform. According to DIVD, as reported by BleepingComputer, the attacker leveraged these previously unknown flaws together to gain access, and the intrusion is described as "AI-driven." Full technical details of the vulnerabilities and the exact mechanics of the breach have not yet been published.

Why it matters

DIVD is a well-known vulnerability-disclosure nonprofit, making this a notable case of an organization focused on securing others being compromised itself. Zammad is widely deployed as a self-hosted, open-source helpdesk/ticketing system, so any organization running it is potentially exposed to the same flaw chain once details emerge. Ticketing systems are attractive targets because they often have broad internal access, handle sensitive customer and internal data, and can serve as a pivot point into wider network infrastructure — which appears consistent with how this breach reportedly unfolded.

What defenders should watch for now

  • Inventory whether your organization runs self-hosted Zammad and check for any vendor advisories or patches as they are released.
  • Until a patch is confirmed, consider restricting external/internet exposure of Zammad instances and reviewing authentication and access logs for anomalous activity.
  • Watch for unusual process execution, outbound connections, or privilege escalation originating from the host(s) running Zammad, since a ticketing app is not a typical source of such activity.
  • Review any integrations or service accounts tied to Zammad for scope — a compromised ticketing system can be used to pivot laterally if it holds broad credentials or network access.
  • Monitor for indicators of automated/AI-assisted exploitation patterns (e.g., unusually rapid, iterative probing or exploitation attempts) as more detail becomes available, since DIVD specifically flagged AI involvement in the intrusion.

Developing story

This is based on an initial disclosure from DIVD with limited technical detail published so far; no CVE identifiers, patch status, or full root-cause analysis are available at this time. We will revisit this item as more information, including any assigned CVEs or vendor guidance, becomes public. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.